One Click Close Comments
One Click Close Comments has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it is fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Exposure Of Sensitive Information To An Unauthorized Actor, behind 1 of the records (100%).
The one issue recorded for One Click Close Comments has a vendor fix available, so running the current release closes it.
All of these findings were reported by stealthcopter. One Click Close Comments is installed on roughly 5,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2024-6546One Click Close Comments <= 2.7.1 - Unauthenticated Full Path Disclosure
Read the full analysisVulnerability Records

One Click Close Comments
Author
Scott Reilly
From the admin listing of posts (‘Edit Posts’) and pages (‘Edit Pages’), a user can close or open comments to any posts to which they have sufficient privileges to make such changes (essentially admins and post authors for their own posts). This is done via an AJAX-powered color-coded indicator. The color-coding gives instant feedback on the current status of the post for comments: green means the post/page is open to comments, red means the post/page is closed to comments. Being AJAX-powered means that the change is submitted in the background after being clicked without requiring a page reload. This plugin will only function for administrative users in the admin who have JavaScript enabled. Links: Plugin Homepage | Plugin Directory Page | GitHub | Author Homepage Developer Documentation Developer documentation can be found in DEVELOPER-DOCS.md. That documentation covers the hooks provided by the plugin. As an overview, these are the hooks provided by the plugin: c2c_one_click_close_comments_click_char : Filter to customize the character, string, or markup used as the indicator used to toggle a post’s comment status.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C